Security
Last updated: 23 July 2026.
This site
This marketing site currently only collects an email address for our waitlist. Even so:
- Every page is served over HTTPS. There's no unencrypted version of this site
- Data is stored on Cloudflare's infrastructure, not on a server we manage ourselves
- We don't ask for or store passwords, card details, or financial information on this site
The Simple MTD app
Once you connect Simple MTD to HMRC and start keeping records, a much stronger set of practices applies, including:
- HMRC access tokens encrypted at rest (AES-GCM) and never exposed to the browser
- Cloudflare D1, our database, also encrypts everything at rest by default
- Server-side checks on every request confirming you can only see your own data
- No card details stored by us at all. Payment is handled entirely by Stripe Checkout and the Stripe Customer Portal
- Structured logging with personal and financial details redacted
- Sign-in by email link only, no password to leak or reuse
We publish this commitment on the record as each protection is actually built, not retroactively after a problem.
Found a security issue?
If you believe you've found a security vulnerability in this site or the Simple MTD app, please email security@simple-mtd.co.uk rather than posting it publicly. We'll acknowledge reports and aim to fix genuine issues promptly.
If you're already a Simple MTD customer, you can also sign in and use the "Contact us" page in the app to report a security concern or ask a question about your account.